{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/isay--24.8.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:moos-ivp:isay:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-85425"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["iSay (\u003c= 24.8.1)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["MOOS-IvP"],"content_html":"\u003cp\u003eThe MOOS-IvP (Mission Oriented Operating Suite - Interval Programming) project contains a critical security vulnerability in its iSay component. This component, often used for text-to-speech or notification messaging within the MOOS environment, fails to adequately sanitize input provided through the SAY_MOOS variable. As of version 24.8.1 and earlier, the application passes the contents of this variable directly into a system shell execution context.\u003c/p\u003e\n\u003cp\u003eAn attacker capable of publishing messages to the MOOS community database (DB) can manipulate the SAY_MOOS variable to include shell command substitution characters, such as backticks or \u0026quot;$( )\u0026quot; syntax. When the iSay process parses these malformed messages, the shell interprets the injected sequences as commands, leading to arbitrary code execution under the privileges of the iSay process. This vulnerability is particularly relevant in autonomous vehicle and robotic systems where MOOS-IvP is deployed to facilitate inter-process communication and task coordination.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains network access to the MOOS community database (MOOSDB) via the configured MOOS port.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious MOOS message containing shell command injection syntax (e.g., \u003ccode\u003eSAY_MOOS = \u0026quot;test \\\u003c/code\u003ewhoami`\u0026quot;`).\u003c/li\u003e\n\u003cli\u003eAttacker publishes the crafted message to the MOOSDB using standard MOOS communication protocols.\u003c/li\u003e\n\u003cli\u003eThe iSay process, subscribed to updates on the SAY_MOOS variable, receives the malicious payload.\u003c/li\u003e\n\u003cli\u003eThe iSay process passes the payload string to a system execution function (e.g., popen or system) without sanitization.\u003c/li\u003e\n\u003cli\u003eThe underlying system shell executes the attacker's injected command.\u003c/li\u003e\n\u003cli\u003eAttacker achieves remote code execution with the permissions of the iSay application.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to execute arbitrary code on the host running the iSay process. Given that MOOS-IvP is frequently utilized in unmanned robotic and autonomous surface vehicles, this could lead to full system compromise, exfiltration of telemetry data, or disruption of mission-critical control software.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch the MOOS-IvP environment by updating to a version beyond 24.8.1 once the vendor provides a remediation.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation within the MOOSDB gateway to restrict the characters allowed in the SAY_MOOS variable.\u003c/li\u003e\n\u003cli\u003eMonitor the iSay process for anomalous child process spawning, such as /bin/sh or /bin/bash executions that originate from the iSay binary.\u003c/li\u003e\n\u003cli\u003eSegment the network to ensure that only authorized nodes can publish to the MOOSDB.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T23:24:19Z","date_published":"2026-09-03T23:24:19Z","id":"https://feed.craftedsignal.io/briefs/2026-09-moos-ivp-rsce/","summary":"The iSay component in MOOS-IvP through 24.8.1 is vulnerable to remote code execution because it passes unsanitized SAY_MOOS variable content directly to a shell, allowing command injection via backticks or substitution syntax.","title":"Remote Code Execution in MOOS-IvP iSay","url":"https://feed.craftedsignal.io/briefs/2026-09-moos-ivp-rsce/"}],"language":"en","title":"CraftedSignal Threat Feed - ISay (\u003c= 24.8.1)","version":"https://jsonfeed.org/version/1.1"}